Total vulnerabilities in the database
XStream through 1.4.9, when a certain denyTypes workaround is not used, mishandles attempts to create an instance of the primitive type 'void' during unmarshalling, leading to a remote application crash, as demonstrated by an xstream.fromXML("<void/>") call.
Software | From | Fixed in |
---|---|---|
debian / debian_linux | 8.0 | 8.0.x |
debian / debian_linux | 9.0 | 9.0.x |
![]() |
- | 1.4.10 |
redhat / jboss_middleware | 1 | 1.x |
redhat / fuse | 1.0 | 1.0.x |
xstream / xstream | - | 1.4.9.x |